English ยท ็ฎไฝไธญๆ
Your work account, your personal account, your side-project org โ
one click apart, right from the menu bar.
Download ยท Quick start ยท How it works ยท FAQ
Important
Unofficial, community-built tool. It is not affiliated with or endorsed by Factory. It only manages accounts you signed into through Factory's official login, it never switches automatically, and it does not touch server-side quotas, billing or organization permissions. Use it in line with Factory's terms and your organization's policies.
If you use Factory Droid with more than one account โ say a company org and a personal one โ
switching normally means signing out, going through the browser OAuth again and hoping you picked the right
profile. Factory Switcher keeps an encrypted snapshot of each login you already have and swaps them for you,
safely, from a tiny FS icon in the menu bar.
| Feature | What you get | |
|---|---|---|
| ๐ | One-click switching | Pick a saved account โ Factory quits gracefully, the login is swapped, Factory reopens. |
| ๐ | Quota at a glance | 5-hour, weekly and monthly remaining % for every account, plus reset times and extra-usage balance when the official API provides them. Refreshes every 5 min (optional). |
| ๐ | Official login only | New accounts are added through the Droid CLI bundled inside your Factory.app, in an isolated home. Browser authorization stays 100% official. |
| ๐ก๏ธ | Backup first, roll back on failure | Every switch is backed up and verified before anything changes. Any failure restores the original login; interrupted runs can be recovered from the menu. |
| ๐ | Encrypted at rest | Login snapshots are AES-GCM encrypted; keys live in the macOS Keychain, never next to the files. Tokens are never printed or logged. |
| ๐ฌ | Carry chosen sessions across accounts (opt-in) | Pick specific local conversations to continue under another account. Backed up first; untouched unless you select them. |
| ๐ชถ | Tiny & native | Swift + AppKit, ~1 MB, zero third-party dependencies, no telemetry, no Dock icon. |
- Confirm โ you see the target account and a reminder that running tasks will stop (can be turned off in Settings).
- Quit gracefully โ Factory is asked to quit normally. Running terminal
droidsessions block the switch; nothing is ever force-killed. - Back up & verify โ the latest (possibly just-rotated) tokens of the current account are saved, then a backup is written and checked.
- Swap login โ the target's encrypted login and key are installed and verified.
- Relaunch โ Factory reopens as the new account. If any step fails, the original login and session markers are restored.
- Grab
FactorySwitcher-*-arm64.zipfrom the latest release and unzip it. - Move
FactorySwitcher.appto a stable place, e.g.~/Applications. - Open it. Because the build is ad-hoc signed and not notarized, macOS will block the first launch: go to System Settings โ Privacy & Security, scroll down and click Open Anyway.
- On first use macOS may ask for Keychain access. Allow it only for the switcher you trust.
Note
Please don't disable Gatekeeper or strip security attributes to run it. If you'd rather not trust a downloaded binary, building from source takes about a minute.
Requires macOS 13+ and Xcode 16 / Swift 6 command-line tools.
git clone https://github.com/lhfer/factory-switcher.git
cd factory-switcher
swift test
bash scripts/build-app.sh # โ dist/FactorySwitcher.app- Launch the app โ an FS item appears in the menu bar (no Dock icon, no window).
- ไฟๅญ / ๅๆญฅๅฝๅ่ดฆๅท (Save / sync current account) โ snapshots the account you're signed into now. Factory keeps running.
- ๆทปๅ ่ดฆๅท๏ผๅฎๆน็ปๅฝ๏ผโฆ (Add account โ official login) โ give it a label; a Terminal opens running Factory's own Droid in an isolated home. Authorize in the browser (tip: use a private window if it auto-signs you into the old account).
- When it says you're logged in, quit Droid in that terminal with Ctrl+C โ not
/logout. The new account is saved automatically. - Click any saved account to switch. After Factory reopens, double-check the email/org shown in Factory before starting work.
Warning
Switching quits and reopens Factory โ running tasks will be interrupted. Finish or save your work first, and
close any droid sessions in your terminals.
Note
The app's interface is currently Simplified Chinese only. English labels above are translations of the menu items.
The full user guide (Chinese) is in docs/USAGE.zh-CN.md and also opens from the menu.
Network access is limited to the official login you start, the official billing-limits endpoint and, for idle accounts, the official token refresh. No analytics, no telemetry, no uploads of your backups.
| What | Where |
|---|---|
| Labels, emails, user/org IDs, preferences | ~/.factory-switcher/state.json |
| Encrypted login snapshots | ~/.factory-switcher/accounts/ |
| Login backups, selected session copies, recovery journal | ~/.factory-switcher/backups/ |
| Isolated homes for official logins | ~/.factory-switcher/logins/ |
| Snapshot & backup encryption keys | macOS Keychain, service local.FactorySwitcher.keys |
Sensitive folders are 0700, files 0600. Session backups contain full conversation text and are not separately
encrypted, and labels/emails are plain metadata โ they rely on file permissions. Turning on FileVault is recommended,
and don't put ~/.factory-switcher in a cloud-synced folder.
Does this give me more quota or bypass limits?
No. It shows the official quota of each account you already own and lets you switch between them by hand. It never switches automatically, never creates accounts and never modifies quotas, billing or org settings. Use multiple accounts only where Factory's terms and your organization allow it.
The browser signs me into the old account when adding a new one.
That's your browser's existing session, not the switcher. Copy the authorization link Droid prints into a private / incognito window and sign in with the account you want to add.
Will my running agent survive a switch?
No โ a switch quits and relaunches Factory. The switcher refuses to proceed while terminal droid processes are
running and never force-kills anything, but anything running inside Factory will stop.
Can I continue a conversation from account A under account B?
Only conversations you explicitly select. The switcher backs them up and removes the org marker from their first line so Droid can open them under the new account. Their content may then be sent to the new account's organization โ never mix confidential work conversations with personal accounts. You can restore the original markers from Backup & restore.
Intel Macs? Older macOS?
Built and tested on Apple Silicon with macOS 13+ APIs. Intel and older systems are unverified โ building from source on Intel may work but isn't tested.
How do I uninstall completely?
Quit the switcher and any login terminal, move ~/.factory-switcher to the Trash, then remove Keychain items with the
service local.FactorySwitcher.keys in Keychain Access. This drops all switcher backups. Do not delete
~/.factory, your Factory sessions or the Factory CLI Keychain item.
- 43 XCTests with synthetic JWTs, an in-memory keychain, fake process/network layers and temp directories โ
covering AES-GCM interop, file permissions/locks/symlinks, rollback on every failure point, crash recovery,
token rotation and selective session sharing. Tests never touch a real account. See
VALIDATION.md. - Compatible with the Factory.app 0.187 / Droid 0.230 storage formats that were current during development. If a future format isn't recognized, the switcher stops instead of guessing.
The official-login isolation pattern and local format handling were informed by
droid-switcher by shariqriazz (MIT). This is an independent
Swift/AppKit implementation with no bundled code or binaries from that project โ see
THIRD_PARTY_NOTICES.md.
MIT ยฉ 2026 lhfer. "Factory" and "Droid" belong to their respective owners.